Search
Find merged stories by title or summary.
InfoSec News Nuggets – 09/04/2026
SonicWall Warns of Two SMA1000 Zero-Days Exploited in Attacks SonicWall is urging customers running its SMA1000 series secure remote access appliances to patch two zero-day vulnerabilities that have already been exploited in the wild, both discovered internally by the vendor. CVE-2026-83548 (CVSS 10. 0) is a pre-authentication SSRF flaw in the Appliance Work Place interface that lets an unauthenticated attacker reach sensitive internal functionality, while CVE-2026-83549 (CVSS 7. 8) is an OS command injection flaw in the Appliance Management Console — Rapid7 notes the two can be chained together for fully unauthenticated remote code execution.
Attackers exploit zero-days in consistently besieged SonicWall product
SonicWall customers are grappling with yet another pair of actively exploited zero-day vulnerabilities in SonicWall SMA 1000 appliances, a product that’s been besieged with recurring defects and attacks over the past nine months. The vendor disclosed and released patches for the defects — CVE-2026-83548 and CVE-2026-83549 — and noted both were already actively exploited in the wild in a security advisory Tuesday. The Cybersecurity and Infrastructure Security Agency added the defects to its known exploited vulnerabilities (KEV) catalog Wednesday. SonicWall customers have confronted a barrage of actively exploited vulnerabilities in SonicWall devices for years. Attackers have consistently exploited newly discovered zero-days and years-old defects in the vendor’s products to break into victim environments.
SonicWall Vulnerabilities Exploited in the Wild
CVE-2026-83548: A critical, unauthenticated server-side request forgery (SSRF) vulnerability in the SMA1000 Appliance Work Place interface. It allows attackers to reach sensitive internal functionality through an unintended access path. CVE-2026-83549: A high-severity OS command injection vulnerability in the Appliance Management Console (AMC). It can allow arbitrary operating-system command execution. These two vulnerabilities can be chained together to achieve unauthenticated remote code execution, allowing attackers to access sensitive functionality and perform unauthorized operations. CVE CVE-2026-83548 CVE-2026-83549 Affected Products SMA1000 Models – 6210, 7210, 8200v running the following versions:
CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners
The U. S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added seven security flaws to its Known Exploited Vulnerabilities (KEV) catalog after they landed in attackers' crosshairs. The vulnerabilities are as follows - CVE-2026-83548 (CVSS score: 10.0) - A server-side request forgery vulnerability in SonicWall SMA 1000 Appliances that could allow a remote unauthenticated
SonicWall reports two major security holes under active exploit
SonicWall on Monday reported two major security holes in its Secure Mobile Access 1000 series appliances, both of which it said are being actively exploited, and published patches for each. Consultants called the holes, one of which permits remote attacks that bypass authentication, highly troubling. In its security alert , SonicWall described the first hole, tracked as CVE-2026-83548 and rated 10 (critical) in severity, as a “Pre-authentication SSRF vulnerability [that] exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized access to sensitive functionality and perform unauthorized operations.”
Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
Overview On September 1, 2026, SonicWall disclosed two vulnerabilities affecting SonicWall SMA1000 appliances that the vendor says are being actively exploited in the wild. The vulnerabilities, CVE-2026-83548 and CVE-2026-83549 , can be chained to achieve unauthenticated remote code execution (RCE) on affected appliances. CVE-2026-83548 is a critical pre-authentication server-side request forgery (SSRF) vulnerability in the SMA1000 Appliance Work Place interface. The flaw has a CVSS v3. 1 base score of 10. 0 and can allow a remote, unauthenticated attacker to access sensitive functionality and perform unauthorized operations through an unintended alternate access path. CVE-2026-83549 is a high-severity OS command injection vulnerability in the Appliance Management Console (AMC). On its own, exploitation requires an authenticated administrator and specific system conditions.
SonicWall Patches Two New Actively Exploited Zero-Days in SMA 1000 VPNs
SonicWall patched two zero-days in SMA 1000 VPNs, including a CVSS 10 pre-auth SSRF flaw, after confirming active exploitation. SonicWall has released security updates for two vulnerabilities in its SMA 1000 VPN appliances that are actively exploited in attacks in the wild. • CVE-2026-83548 (CVSS 10.0) is a pre-authentication SSRF vulnerability in the Appliance Work Place interface. A remote unauthenticated attacker could exploit it to access sensitive functionality and perform unauthorized operations. • CVE-2026-83549 (CVSS 7.8) is a post-authentication operating system command injection flaw in the Appliance Management Console (AMC). A remote attacker authenticated as an administrator could exploit it under specific conditions to execute arbitrary commands and achieve remote code execution.
SonicWall security advisory (AV26-872)
Serial Number: AV26-872 Date: September 2, 2026 As of September 1, 2026, SonicWall is affected by a vulnerability in the following product: • SMA1000 - 6210, 7210, 8200v • 12.4.3-03453 (platform-hotfix) and older versions • 12.5.0-02835 (platform-hotfix) and older versions SonicWall indicates that CVE-2026-83548, CVE-2026-83549 are being exploited. The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. • Security Advisory • SonicWall Security Advisories SonicWall security advisory (AV26-872) - Canadian Centre for Cyber Security
CISA Adds Seven Known Exploited Vulnerabilities to Catalog
CISA has added seven new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. • CVE-2026-9586 Sangoma Switchvox SQL Injection Vulnerability • CVE-2026-48710 Kludex Starlette HTTP Request/Response Smuggling Vulnerability • CVE-2026-49869 Kestra OSS OS Command Injection Vulnerability • CVE-2026-59822 BerriAI LiteLLM Improper Authentication Vulnerability • CVE-2026-82329 JFrog Artifactory Improper Authentication Vulnerability • CVE-2026-83548 SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability • CVE-2026-83549 SonicWall SMA1000 Appliances OS Command Injection Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise.
Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain
SonicWall has released security updates to address two security flaws impacting its Secure Mobile Access (SMA) 1000 series VPN appliances that have been exploited in zero-day attacks. The vulnerabilities, discovered internally by SonicWall's William Perry and Adam Babis, are listed below - CVE-2026-83548 (CVSS score: 10.0) - A pre-authentication SSRF vulnerability in the Appliance
SonicWall SMA 1000 appliances under attack via zero-day flaws
Attackers are exploiting two previously undisclosed vulnerabilities (CVE-2026-83548, CVE-2026-83549) in SonicWall SMA 1000 appliances, the vendor confirmed on Tuesday. The vulnerabilities (CVE-2026-83548, CVE-2026-83549) The SonicWall SMA 1000 series is a line of secure remote access appliances (SSL VPN gateways) built for scale. They are used regularly by medium to large enterprises, government agencies, and managed security service providers. CVE-2026-83548 is a pre-authentication server-side request forgery (SSRF) flaw in the Appliance Work Place interface, and allows … More → The post SonicWall SMA 1000 appliances under attack via zero-day flaws appeared first on Help Net Security .
SonicWall Warns of Two SMA1000 Zero-Days Exploited in Attacks
The vulnerabilities CVE-2026-83549 and CVE-2026-83548 can be chained for unauthenticated remote code execution. The post SonicWall Warns of Two SMA1000 Zero-Days Exploited in Attacks appeared first on SecurityWeek .
CVE-2026-83548 - SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
SonicWall SMA1000 Appliances contains a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to gain unauthorized access to sensitive functionality and perform unauthorized operations.
You've reached the end of current stories for this search.
